Open
Cached
·
just now
77/100
SECURITY SCORE
Certificate Information
Subject
CN=staging.cms.ielts.cambri.ai
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
December 08, 2025
Valid Until
March 08, 2026
89 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
5C:7B:7E:04:31:21:95:A7:60:58:1A:33:6E:74:4E:68:10:95:C2:6F:09:B3:4D:82:BB:D8:BD:13:89:5C:12:1F
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
sunnah-life.banglafighter.net
campus.ia.up.ac.za
www.aoismail.com
aqode.com
aquasimple.co
app.astrakk.com
badfruit.app
homolog.beeprivacy.com.br
bestellen.bowling-kueche.de
buffer.energy
staging.cms.ielts.cambri.ai
sdhealth.cheart.io
chrishenke.us
www.greenways.co.in
preview.vrelovod-osijek.com.hr
click.afnobazar.com.np
zettasoft.com.uy
connectingvision.ro
constantlyconnie.me
crewpin.in
jrb.criptan.es
davealger.info
kofevar.davvie.com
depot-tracker.com
gnosis.doll.network
yajinonfon.eya.digital
app.flowcharts.ai
garyfrankpainting.com
www.garyfrankpainting.com
getmyfavorites.com
movies.ghiath.net
gsc-holdings.net
globalmemo.hashito.biz
app.iconparkingsystems.com
isaacbejarano.com
itspiss.com
www.kismehecskeetelbar.hu
www.kormanik.me
kriswipe.app
www.learousevents.in
kcts.web-demo.localpublic.org
www.lockdown.memorial
mag.studio
qr.marcrufeis.de
www.massage-christchurch.co.nz
ark.merthincloud.net
beta.mixi.nyc
money-hooks.com
murcs.app
app.nextuprecruitment.com
nobeldeveloper.com
www.novaflame.ca
photo.nurzen.group
staging.admin.ogiso.io
live.payr.org.in
www.parkinglesalqueries.com
phoenixcommand.net
www.pikorua.in
link.placehunter.com
play2x.run
museacms.verify.podego.com
trigger.poster.land
rad.day
researcher.researchout.com
rowan.fyi
sai-tek.site
serafettingazibaba.dev
seraguas.es
cemasys.shed.no
eldorado.shed.no
fortum.shed.no
hk.shed.no
infinitum.shed.no
fortum.shedtest.no
glittertind.shedtest.no
oda.shedtest.no
thon.shedtest.no
signup.sheet.supply
ym-app-stg.site-ymobile.net
www.slimarfaoui.com
sparplay.com
www.sparplay.com
www.storywise.app
the-running-man-lucca.swservice.biz
evquotes.teamenoch.com
linkdev.thegift.pt
orders.apps.tiendex.com
www.tizzly.com
www.toost.store
trimemo.tech
craftbeer.truffle.fan
dev.unitedlogistics.app
www.visual.pics
horcel.wiki.br
windupmusic.ca
auth.wondermap.app
link-daya.mokitadev.xituz.com
www.youngspacegroup.com
zilbauer.me
pos-s.zobaze.com
Other domains in certificate